Sign inSign up
Gitea

dhi.io/gitea

Gitea 1.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

1-alpine-dev, 1-alpine3.24-dev, 1.27-alpine-dev, 1.27-alpine3.24-dev, 1.27.3-alpine-dev, 1.27.3-alpine3.24-dev

Index digest:

sha256:015c35a319ca4dd4a957d63954c18069c4f09185e8e6a2da6aafcd748b48c712

Manifest digest:

sha256:5dbec2708a207a75ce3216615db6022c327069dbcd3a4effd556f65def80343a

Size

88.58 MB

Last pushed

8 hours ago

Vulnerabilities

2
8
1
0
3

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gitea:1-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gitea:1-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gitea@sha256:5d04dd507fcf0118a1cb0428c330ffc5e5cff480d349db9576d71e7b19f230a0
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gitea@sha256:b233a4c107ac505a61140457884f6d6e8f1f2436ac459ee2f1d25531ea4029f6
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gitea@sha256:0c89e85f134e7e34d5051afae96d37c3d273c013f77f3cb3637546a6c8dd7c6f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gitea@sha256:84aeeef4d434373e68f39c73e7a3fe4d3927460f9712b8e1a5e315f23f9b98f5
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gitea@sha256:e1b45c3e64b040dc9b3ea231b4313dc545a2aa6f12ffc9de1df9f9070b115825
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gitea@sha256:f614626e13f793e1789f42f2acefbd3c8be7ca50f02a2b2881f6d6eac949d3d8
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gitea@sha256:40fe32d06718a625245c31ff111184376457a861b4a56fe0003a0ee3cc40923b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gitea@sha256:b768c6544c1f2efab6a4b7857c3a5fcdfc98084e9d59fa0ef07b1b81d2d9ef1d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gitea@sha256:c8cca3bbfb447dde12fdb1e774577fddc261523a9ff206fe3c4b36809d7704cd
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gitea@sha256:c28e1f6c04a6afa47ede4961eedd641d3408f1d88cae7abe6c1a39a0c1b4a854
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gitea@sha256:cb0a8f511322dfadf8d56e702acfb9c966a72272c2379c156668c49377669bc2
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gitea@sha256:d4ec8e29998993019ed46a9545c44c9d48413024afe34abad76febe453eb40a8
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gitea@sha256:3899518846fd369559386344ed6dbca3d619f3dd00a68f79369d564cb11a49b1
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gitea@sha256:09b3a707d6455e30e484eb7445db446780601b983a259cf2264835ff566c73ec
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gitea@sha256:99bcb8724893bfff6d4ece24df77bbf5162618834ad998b235d54e01d3dc7abe